Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-20614

Опубликовано: 12 янв. 2022
Источник: redhat
CVSS3: 4.3

Описание

A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

A missing permissions verification vulnerability was found in the Jenkins Mailer plugin. The form validation method does not perform a permission check which allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkinsAffected
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 4jenkinsAffected
Red Hat OpenShift Container Platform 4jenkins-2-pluginsAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862->CWE-276
https://bugzilla.redhat.com/show_bug.cgi?id=2044497jenkins-2-plugins/mailer: does not perform a permission check in a method implementing form validation

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

CVSS3: 4.3
github
около 4 лет назад

Incorrect Permission Assignment for Critical Resource in Jenkins Mailer Plugin

4.3 Medium

CVSS3